5.5
CVSSv3

CVE-2016-2415

Published: 18/04/2016 Updated: 21/04/2016
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 632
Vector: AV:N/AC:M/Au:N/C:C/I:N/A:N

Vulnerability Summary

exchange/eas/EasAutoDiscover.java in the Autodiscover implementation in Exchange ActiveSync in Android 5.0.x prior to 5.0.2, 5.1.x prior to 5.1.1, and 6.x prior to 2016-04-01 allows malicious users to obtain sensitive information via a crafted application that triggers a spoofed response to a GET request, aka internal bug 26488455.

Vulnerable Product Search on Vulmon Subscribe to Product

google android 6.0.1

google android 5.0

google android 5.1.0

google android 5.0.1

google android 6.0

google android 5.1